2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-60794MEDIUM6.5Session tokens and passwords in couch-auth 0.21.2 are stored in JavaScript objects and remain in memory without explicit...
CVE-2025-5092MEDIUM6.4Multiple plugins and/or themes for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled ligh...
CVE-2025-41076MEDIUM6.5In version 6.13.0 of LimeSurvey, any external user can cause a 500 error in the survey system by sending a malformed ses...
CVE-2025-40605MEDIUM5.3A Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file...
CVE-2025-13469MEDIUM4.8A security vulnerability has been detected in Public Knowledge Project omp and ojs 3.3.0/3.4.0/3.5.0. Impacted is an unk...
CVE-2025-13450MEDIUM5.4A vulnerability was determined in SourceCodester Online Shop Project 1.0. Impacted is an unknown function of the file /s...
CVE-2025-13443MEDIUM6.5A vulnerability was detected in macrozheng mall up to 1.0.3. Affected by this issue is the function delete of the file /...
CVE-2025-12778MEDIUM5.3The Ultimate Member Widgets for Elementor – WordPress User Directory plugin for WordPress is vulnerable to unauthorized ...
CVE-2025-12502MEDIUM6.8The attention-bar WordPress plugin through 0.7.2.1 does not sanitize and escape a parameter before using it in a SQL sta...
CVE-2025-13415MEDIUM5.4A vulnerability was identified in icret EasyImages up to 2.8.6. This affects an unknown part of the file /app/upload.php...
CVE-2025-58181MEDIUM5.3SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, al...
CVE-2025-47914MEDIUM5.3SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the progra...
CVE-2025-13412MEDIUM6.1A vulnerability was determined in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this issue is some unkn...
CVE-2025-13147MEDIUM5.3Server-Side Request Forgery (SSRF) vulnerability in Progress MOVEit Transfer.This issue affects MOVEit Transfer: before ...
CVE-2025-63214MEDIUM6.5An issue was discovered in bridgetech VBC Server & Element Manager, firmware version 6.5.0-10 , 6.5.0-9, allowing unauth...
CVE-2025-63212MEDIUM6.5GatesAir Flexiva-LX devices on firmware 1.0.13 and 2.0, including models LX100, LX300, LX600, and LX1000, expose sensiti...
CVE-2025-51662MEDIUM5.4A stored cross-site scripting (XSS) vulnerability is found in the text sharing feature of FileCodeBox version 2.2 and ea...
CVE-2025-36371MEDIUM6.5IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 are impacted by obtaining an information vulnerability in the database plan cache impl...
CVE-2025-65100MEDIUM6.9Isar is an integration system for automated root filesystem generation. In versions 0.11-rc1 and 0.11, defining ISAR_APT...
CVE-2025-64759MEDIUM6.1Homarr is an open-source dashboard. Prior to version 1.43.3, stored XSS vulnerability exists, allowing the execution of ...
CVE-2025-63211MEDIUM6.1Stored cross-site scripting vulnerability in bridgetech VBC Server & Element Manager, firmware versions 6.5.0-9 thru 6.5...
CVE-2025-65089MEDIUM6.5XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to ver...
CVE-2025-65032MEDIUM6.5Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference ...
CVE-2025-65031MEDIUM6.5Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an improper authorization flaw in th...
CVE-2025-65028MEDIUM6.5Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now